Domain Groups

T1069.002

Sub-technique of T1069 Permission Groups Discovery.View on attack.mitre.org

About this technique

Adversaries may attempt to find domain-level groups and permission settings. The knowledge of domain-level permission groups can help adversaries determine which groups exist and which users belong to a particular group. Adversaries may use this information to determine which users have elevated permissions, such as domain administrators.

Commands such as net group /domain of the Net utility, dscacheutil -q group on macOS, and ldapsearch on Linux can list domain-level groups.

Detection rules37

Rules on DetectionCode tagged with T1069.002.

Sigma14

RuleLevelLog source
BloodHound Collection Fileshighwindows / file_event
HackTool - Bloodhound/Sharphound Executionhighwindows / process_creation
HackTool - SharpView Executionhighwindows / process_creation
Malicious PowerShell Commandlets - PoshModulehighwindows / ps_module
Malicious PowerShell Commandlets - ProcessCreationhighwindows / process_creation
Malicious PowerShell Commandlets - ScriptBlockhighwindows / ps_script
PUA - AdFind Suspicious Executionhighwindows / process_creation
Reconnaissance Activityhighwindows / NULL
Renamed AdFind Executionhighwindows / process_creation
Suspicious Active Directory Database Snapshot Via ADExplorerhighwindows / process_creation
Active Directory Database Snapshot Via ADExplorermediumwindows / process_creation
ADExplorer Writing Complete AD Snapshot Into .dat Filemediumwindows / file_event
Potential Active Directory Reconnaissance/Enumeration Via LDAPmediumwindows / NULL
Active Directory Group Enumeration With Get-AdGrouplowwindows / ps_script

Splunk23

RuleTypeRiskData source
Detect AzureHound Command-Line ArgumentsTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
Detect AzureHound File ModificationsTTPNULLSysmon EventID 11
Detect SharpHound Command-Line ArgumentsTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
Detect SharpHound File ModificationsTTPNULLSysmon EventID 11
Detect SharpHound UsageTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
Domain Group Discovery with AdsisearcherTTPNULLPowershell Script Block Logging 4104
Domain Group Discovery With DsqueryAnomalyNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
Domain Group Discovery With NetHuntingNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
Domain Group Discovery With WmicHuntingNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
Elevated Group Discovery With NetTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
Elevated Group Discovery with PowerViewHuntingNULLPowershell Script Block Logging 4104
Elevated Group Discovery With WmicTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
GetAdGroup with PowerShellHuntingNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
GetAdGroup with PowerShell Script BlockHuntingNULLPowershell Script Block Logging 4104
GetDomainGroup with PowerShellTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2

Groups13

Software23

Campaigns2

Procedure examples38

Groups13

Used byProcedure example
GroupDragonfly

Dragonfly has used batch scripts to enumerate administrators and users in the domain.

GroupFIN7

FIN7 has used the command `net group "domain admins" /domain` to enumerate domain groups.

GroupINC Ransom

INC Ransom has enumerated domain groups on targeted hosts.

GroupInception

Inception has used specific malware modules to gather domain membership.

GroupKe3chang

Ke3chang performs discovery of permission groups net group /domain.

GroupLAPSUS$

LAPSUS$ has used the AD Explorer tool to enumerate groups on a victim's network.

GroupMedusa Group

Medusa Group has utilized the `net group` command to query domain groups within the victim environment.

GroupMustang Panda

Mustang Panda has leveraged AdFind to enumerate domain groups.

View all 13 groups examples

Software23

Used byProcedure example
ToolAdFind

AdFind can enumerate domain groups.

MalwareBADHATCH

BADHATCH can use `net.exe group "domain admins" /domain` to identify Domain Administrators.

MalwareBlackCat

BlackCat can determine if a user on a compromised host has domain admin privileges.

ToolBloodHound

BloodHound can collect information about domain groups and members.

ToolBrute Ratel C4

Brute Ratel C4 can use `net group` for discovery on targeted domains.

MalwareCobalt Strike

Cobalt Strike can identify targets by querying account groups on a domain contoller.

ToolCrackMapExec

CrackMapExec can gather the user accounts within domain groups.

Tooldsquery

dsquery can be used to gather information on permission groups within a domain.

View all 23 software examples

Campaigns2

Used byProcedure example
CampaignC0015

During C0015, the threat actors use the command `net group "domain admins" /dom` to enumerate domain groups.

CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 used AdFind to enumerate domain groups.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.